Logo
vulnerabilityCVE-2026-56022
Name
CVE-2026-56022
Source
NVD ( link)Debian ( link)
Description
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.640.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
webmin
Exploitable

Vulnerability Ratings#


6.9
CVSSv4
5.3
CVSSv31
NaN
other
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
1.850
Exploitable
yocto
master
2.653
Not Affected